Live data from Hacker News

DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

gao.gov

81–90 of 225 posts

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#81
post #68

Earlier quoted context omitted.

> an MBA only led business with no influence from engineering/security As an MBA holder and avid HN user, I take issue with that statement...

You should note specific issues, rather than a general complaint.

I’ll bite. There was no indication in the article of anyone with an MBA in particular being responsible for these issues. The reasoning reads as: “lots of stuff is going wrong” ==> “must be because they have management with MBAs”

Why try to make this link if it isn’t there? What if I replace MBAs with ‘foreigners’, ‘women’, ‘people who read HN’, etc?

Why do we need this? Does blaming non-technical people for the failures of management make us feel better about ourselves?

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#82
post #51

Earlier quoted context omitted.

The modern DoD is based around the Asst Sec Defs and business processes put in place by Robert McNamara, who came from Ford. It's all stats and businees. Engineers and scientists are generally considered a sideshow, a workforce to quantitate.

This is, unfortunately, all too true. > “An interesting question is, ‘Where did the name, dynamic programming, come from?’ The 1950s were not good years for mathematical research. We had a very interesting gentleman in Washington named Wilson. He was Secretary of Defense, and he actually had a pathological fear and hatred of the word, research. I’m not using the term lightly; I’m using it precisely. His face would su…

[deleted]

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#83
post #68

Earlier quoted context omitted.

> an MBA only led business with no influence from engineering/security As an MBA holder and avid HN user, I take issue with that statement...

You should note specific issues, rather than a general complaint.

When people blame things on MBAs here, they tend to not elaborate with specifics either.

MBAs are used as straw man punching bags on HN. Anything that goes wrong with a company where there’s the perception that the “obvious technical solution” was ignored, is blamed on this nebulous cabal of MBAs, who are apparently hired in droves just to sabotage their employer. For some reason it’s totally ok to vaguely blame the business folks.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#84
post #72

Earlier quoted context omitted.

They will be in for a surprise: Using those massive buggy systems is not one bit easier for the hackers than for the actual users. Maybe the many bugs in those huge systems will turn out to be the best protection against enemy takeover... not actually too crazy an idea, when I think of biology and the mess that are biological systems, where even errors are vital for the functioning of the whole system (e.g. accidenta…

It's not about taking over. Disabling them is sufficient.

Or just being a passive viewer of what the system is managing

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#85
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

"In operational testing, DOD routinely found mission-critical cyber vulnerabilities in systems that were under development, yet program officials GAO met with believed their systems were secure and discounted some test results as unrealistic. "

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#86
post #23

I was an operator on a weapon system within the last decade that did not use encryption. I was horrified, naturally, but the explanations were: 1. Well, this is rapid deployment, we can't have everything. 2. The enemy here is fairly low-tech. Shouldn't be a problem. Needless to say, I'm not surprised by this report.

The catch is that on DOD systems, encryption is very difficult to add. That is, to be certified by the NSA and compatible with the military key infrastructure. So its better to avoid mentioning it unless its forced on you. Better is a relative term here. I mean, in terms of cost and effort to add. Not security.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#87
post #7

Earlier quoted context omitted.

>Multiple weapon systems used commercial or open source software, but did not change the default password when the software was installed, which allowed test teams to look up the password on the Internet and gain administrator privileges for that software.

Even worse is that institutional problem where you have people constantly cycling on and off of this hardware that was never designed for a multi-user environment, so default passwords are the order of the day. At best they changed the password and then put it on a sticky note attached to the monitor. The last thing you want is someone forgetting their password to their tactical system while out at sea and having to…

They'd probably helicopter the IT guy in to reset it but still I'm going to posit that they have a procedure for this that may not require physical access and may have remote-access via a secure line.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#88
post #16

The US is going to lose a war this way.

Is there any reason to believe the state of Russian/Chinese/etc. security is any better in this regard?

US military strategy and tactics are much more reliant on high-tech advantages than other countries though. If everyone’s tech all goes down, we’re going to be hit a lot harder.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#89
post #2

The good stuff is in the PDF: https://www.gao.gov/assets/700/694913.pdf - Running a port scan caused the weapons system to fail - One admin password for a system was guessed in nine seconds - "Nearly all major acquisition programs that were operationally tested between 2012 and 2017 had mission-critical cyber vulnerabilities that adversaries could compromise." - Taking over systems was pretty much playing on easy mod…

My thoughts on this are always related to "skin in the game": does it matter personally to the people making and procuring the systems, especially at senior management level, whether it actually works?

Back in WW2 it definitely did, especially in the UK where bombing had no respect for the class system. Winning or losing the war would make a personal difference.

But since then? All the wars have been overseas with no real threat to the mainland US; there was a real technological race against the Soviet Union, but that ended in the 1990s. The post-911 wars were more of an excuse to settle scores and play the Great Game than a real effort against terrorism (no pursuit of the Saudis for example).

The consequence is that the main thing that matters is selling the technology to the Pentagon, or promoting a career inside it. Nobody really believes that if they procure a crappy IT system the enemy is going to fly a 747 into their office. Someone might get killed, but nobody they know or who matters, and it's never going to come back to the project manager or procurement person who made terrible, expensive, uninformed choices about technology.

Re: DOD Just Beginning to Grapple with Scale of Weapon Systems Vulnerabilities

#90

Not to play the Whataboutism card, (proceeds to play whataboutism card), but has anybody pen tested the Soviet's or Chinese' systems? Just thinking this isn't a U.S. only problem.

"The Soviet Union... I thought you guys broke up?"

https://youtu.be/yFNRlvEh7ok

Post reply on HN